Domain 3 - Legal Issues, Contracts and Electronic Discovery Flashcards
1
Q
What are the key Australian Data Protection Laws?
A
- 1988 Privacy Act that was amended in 2017 to add security breach notification
- Australian Consumer Law (ACL) which provides consumers protection from poor conduct from providers.
2
Q
What are the key laws in China?
A
- 2017 Cybersecurity Law - requires network operators to implement TOMs, incident response plan, e-evidence, vulnerability disclosure, and risk management reporting.
- Measures on the security of cross-border transfers of personal information - specifies categories of data that has to stay in China.
3
Q
What are the key laws in Japan?
A
Japan has multiple data protection laws.
- Act on the Protection of Personal Information
- Multiple health sector laws applicable to Pharmacists, Nurses etc.
- Prohibits transfer of information to third parties without consent unless destination country has equivalent protection.
4
Q
What are the key EU laws?
A
- GDPR
2. NIS2 Directive
5
Q
What are the obligations GDPR imposes on companies?
A
- Companies must keep records of processing activities (ROPA)
- Privacy Impact Assessments must precede certain processing
- Services must be privacy by design and privacy by default.
- Processing of personal data requires data subject’s unambiguous consent.
- Breach Notification
- Cross-border transfers require a) equivalent protection b) SCC c) binding corporate rules d) industry code of conduct.
6
Q
Under GDPR what are the rights of the data subject?
A
- Object to use of their data
- Information on how their data is used
- Right to be forgotten
- Right to have data corrected or erased
- Right to data portability.
7
Q
What is NIS and its requirements?
A
Network Information Security is a directive that member states must implement into national law.
Requirements on OES:
- TOMs for information system
- Notifying competent authorities
- Evidence of implementation of effective security policies through audits
- Also covers providers of digital services (e.g. Cloud Service Providers)
8
Q
How are US laws on data protection structured?
A
- Federal and State Laws
- They tend to be sectoral - e.g. HIPAA for health, GLBA for Finance, COPPA for Child Privacy etc.
- States and their attorney generals also impose have fair practice act which protect consumers from bad corporate behavior
9
Q
What does contracts and provider selection involve?
A
- Internal due diligence - is cloud use permitted?
- Monitoring testing and updating - new laws and control effectiveness change over time.
- External due diligence - review all relevant aspects of CSP before procuring their services (SLAs, Certs, Service Terms etc.)
- Contract negotiations - review contracts even if they are not negotiable.
- Reliance on Third-party audits and attestations